CVE-2017-18503: XSS
Published Aug 12, 2019
·Updated
The twitter-cards-meta plugin before 2.5.0 for WordPress has XSS.
Affected Software
1 affected component
WPDeveloper Twitter Cards Meta Wordpress<2.5.0
Event History
Aug 12, 2019
CVE Published
via MITRE·03:36 PM
Data Sourced
via MITRE·03:36 PM
Description
Frequently Asked Questions
1
What is CVE-2017-18503?
CVE-2017-18503 is a vulnerability in the twitter-cards-meta plugin before version 2.5.0 for WordPress that allows for cross-site scripting (XSS) attacks.
2
How severe is CVE-2017-18503?
CVE-2017-18503 has a severity rating of 6.1, which is considered medium.
3
How does CVE-2017-18503 affect WordPress?
CVE-2017-18503 affects WordPress by allowing for cross-site scripting (XSS) attacks through the twitter-cards-meta plugin before version 2.5.0.
4
Is there a fix for CVE-2017-18503?
Yes, to fix CVE-2017-18503, users should update the twitter-cards-meta plugin to version 2.5.0 or later.
5
Where can I find more information about CVE-2017-18503?
You can find more information about CVE-2017-18503 on the official WordPress plugin page: https://wordpress.org/plugins/twitter-cards-meta/#developers